[ALPINE:CVE-2023-30589] openjdk17 vulnerability

Severity High
Affected Packages 29
Fixed Packages 29
CVEs 1

[From CVE-2023-30589] The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).

The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20

Package Affected Version
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=riscv64&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.16 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-edge < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.18 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.17 < 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.16 < 17.0.9_p8-r0
Package Fixed Version
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=riscv64&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.16 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-edge = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.18 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.17 = 17.0.9_p8-r0
pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.16 = 17.0.9_p8-r0
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge x86_64
Affected pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 x86_64
Affected pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 x86_64
Fixed pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 x86_64
Affected pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 x86_64
Fixed pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 x86_64
Affected pkg:apk/alpine/openjdk17?arch=x86_64&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 x86_64
Fixed pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge x86
Affected pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge x86
Fixed pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 x86
Affected pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 x86
Fixed pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 x86
Affected pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 x86
Fixed pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 x86
Affected pkg:apk/alpine/openjdk17?arch=x86&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 x86
Fixed pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge s390x
Affected pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge s390x
Fixed pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 s390x
Affected pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 s390x
Fixed pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 s390x
Affected pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 s390x
Fixed pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 s390x
Affected pkg:apk/alpine/openjdk17?arch=s390x&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 s390x
Fixed pkg:apk/alpine/openjdk17?arch=riscv64&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge riscv64
Affected pkg:apk/alpine/openjdk17?arch=riscv64&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge ppc64le
Affected pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 ppc64le
Affected pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 ppc64le
Fixed pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 ppc64le
Affected pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 ppc64le
Fixed pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 ppc64le
Affected pkg:apk/alpine/openjdk17?arch=ppc64le&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 ppc64le
Fixed pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge armv7
Affected pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge armv7
Fixed pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 armv7
Affected pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 armv7
Fixed pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 armv7
Affected pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 armv7
Fixed pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 armv7
Affected pkg:apk/alpine/openjdk17?arch=armv7&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 armv7
Fixed pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge armhf
Affected pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge armhf
Fixed pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 armhf
Affected pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 armhf
Fixed pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 armhf
Affected pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 armhf
Fixed pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 armhf
Affected pkg:apk/alpine/openjdk17?arch=armhf&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 armhf
Fixed pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-edge alpine openjdk17 = 17.0.9_p8-r0 alpine-edge aarch64
Affected pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-edge alpine openjdk17 < 17.0.9_p8-r0 alpine-edge aarch64
Fixed pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.18 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.18 aarch64
Affected pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.18 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.18 aarch64
Fixed pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.17 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.17 aarch64
Affected pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.17 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.17 aarch64
Fixed pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.16 alpine openjdk17 = 17.0.9_p8-r0 alpine-3.16 aarch64
Affected pkg:apk/alpine/openjdk17?arch=aarch64&distro=alpine-3.16 alpine openjdk17 < 17.0.9_p8-r0 alpine-3.16 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...